Artificial intelligence

Sovereign, GDPR-compliant AI for small businesses in Nice

Using AI without exposing your data comes down to four decisions taken before the project starts: where the model runs — a professional offering hosted in the European Union, or execution on your own infrastructure; what is actually sent to it, once the data has been pseudonymised and the document scope restricted; who signs off before a document goes out; and what you are able to show, from the register of processing activities to the impact assessment. MZ Informatique deals with all four at the scoping stage and hands you the paperwork.

Where does your data go when you use AI?

That is the first question to ask, and it is settled before a line is written. Three answers are possible, and we set them out explicitly at the scoping stage. A consumer online service: your data goes to a vendor, often outside the European Union, and the terms of use do not always rule out reusing it. That is what a great many employees do today, without their employer knowing. A professional offering hosted in the European Union, whose contract explicitly excludes reusing your data to train models. A model run on your own infrastructure, where no data leaves your network.

The right answer depends on how sensitive the data in the use case is, not on a matter of principle. Sorting sales email and analysing medical records do not call for the same judgement.

What does "sovereign AI" actually mean?

Three things you can verify, not a slogan. The hosting location: the servers that run the model and store the intermediate data sit inside the European Union, and that is written into the contract. The vendor's legal position: a company subject to extraterritorial legislation can be compelled to hand over data even when it is hosted in Europe; the point is worth raising rather than dodging. Reversibility: can you change model without rewriting the whole chain? We always design the integration so that the model can be swapped out.

European models exist and are usable in production — Mistral AI sits in our technical stack alongside the other providers. For the most sensitive processing, running the model locally on your infrastructure remains the safest option: less spectacular, but entirely under your control.

  • Hosting inside the European Union, written into the contract.
  • An explicit exclusion of any reuse of your data for training.
  • A replaceable model: the integration does not depend on a single provider.
  • Execution on your own infrastructure when the data demands it.

How do you limit what is sent to the model?

Through minimisation, which also happens to be the most effective technique. Three levers: anonymising or pseudonymising personal data before processing — a file number is almost always enough where a name and an address would otherwise be sent; restricting the document scope to what the use case genuinely needs, never the whole file server; and setting retention periods for the exchanges, the logs and the intermediate files, with an automatic purge.

Those three levers cut the legal risk, the processing cost and the attack surface at the same time. It is one of the rare subjects where compliance and efficiency pull in the same direction.

What place is there for human sign-off?

A central one, and it rests on law as much as on practice. The GDPR governs decisions producing legal or similarly significant effects taken solely on the basis of automated processing: in plain terms, an AI does not decide in a human's place on a hiring, a loan, a sanction or a termination. We turn those use cases down, including when they are asked for.

On everything else the rule is the same as in our other projects: the AI prepares, a human signs off before anything goes to a client, a supplier or a public body. That requirement is agreed at the scoping stage and shows up in the costing: the level of checking is one of the two factors that weigh most on the price of a project.

Applicable framework: the GDPR (notably articles 22, 33 and 35), the CNIL guidance on AI, and the European artificial intelligence regulation, whose obligations apply in stages. To be validated by your own legal adviser for your particular case.

What must you be able to show?

Three documents, which we supply in writing at the end of the project. The entry of the processing in the register: purpose, categories of data, recipients, retention periods, security measures. Informing the people concerned: employees, clients or candidates must know that automated processing takes place, and where. The impact assessment where the processing warrants one, for instance with sensitive data or systematic monitoring.

We follow the guidance the CNIL has published on artificial intelligence rather than asking you to take our word for it. And when a piece of processing strikes us as too sensitive to be outsourced, we say so and propose a local alternative rather than pushing it through.

This subject cannot be separated from the security of the rest of your information system: a perfectly compliant assistant sitting on a network whose remote access is wide open protects nothing. See our cybersecurity pillar for small businesses in Nice.

Three judgements

The hosting choice is made before the project, not after

Each use case is ranked by how sensitive its data is. That ranking determines the way the model is run.

Sensitivity of the dataWay the model is run
Public or unremarkable data, no personal dataA professional offering hosted in the European Union.
Ordinary personal data (clients, suppliers)European hosting, pseudonymisation before processing, short retention periods.
Sensitive data, or data covered by professional secrecyThe model runs on your own infrastructure; no data leaves the network.
A decision with a legal effect on a personOut of scope. We turn the use case down.

Frequently asked questions

AI and the GDPR: what we get asked

Will our data be used to train a public model?

No. We only use professional offerings whose terms explicitly exclude reusing client data for training, with hosting inside the European Union. For the most sensitive data we can run the model on your own infrastructure, with no data leaving your network.

Our staff already use online AI tools: what should we do?

That is the most common situation, and a ban on its own never works. We recommend providing a supervised alternative — a professional tool hosted in Europe, accessible and at least as convenient — then writing a short usage rule saying what may and may not be put into it. It is as much a security matter as a compliance one.

Does every AI project need an impact assessment?

No, only where the processing is likely to create a high risk for individuals: sensitive data, systematic monitoring, large-scale cross-referencing of sources. We raise the question at the scoping stage and tell you whether your case warrants one; the final decision rests with your data controller, with your legal adviser where appropriate.

Can an AI decide on its own in our company?

Not on decisions producing legal or similarly significant effects for a person: hiring, credit, sanctions, termination. The GDPR governs such automated processing strictly and we turn those use cases down. On everything else the AI prepares and a human signs off: that is a constant design rule in our projects.

Is AI compatible with your obligations?

A free half-day scoping session in Nice, Sophia Antipolis, Cannes or Monaco, which deals with the data question before the question of tools.